IT Engineer II - IAM
- AI
- Okta
- Identity Management
- RBAC
- Bash
- PowerShell
- Python
- MacOS
- AWS
- Azure
- GCP
- SCIM
- SAML
- OIDC
- OAuth
- HRIS
About Judi Health
Judi Health is a health technology company providing benefit administration solutions to employers, unions, health plans, and government entities. Judi Health replaces fragmented, outdated systems with the industry's first Unified Claims Processing™ architecture, seamlessly consolidating pharmacy and medical benefit administration on a single, secure platform. By delivering true price transparency, eliminating unnecessary middleman fees, and leveraging advanced AI-powered care delivery, Judi Health helps clients achieve unprecedented operational efficiency and service levels.
At Judi Health, we're deploying the infrastructure our country needs to deliver the healthcare we all deserve. We are the intelligence platform powering benefits plans for millions of Americans and proudly leading the next generation of care. To learn more, visitwww.judi.health.
Location: Hybrid 3 days a week in-office (NYC, Denver, CO or Charlotte, NC)Â
Position SummaryÂ
The IT Engineer II is a mid-level technical contributor responsible for independently delivering complex IT solutions and leading medium-scale initiatives that improve reliability, security, and user experience. This role serves as a key escalation point for IT Engineer I staff, drives cross-functional projects, and applies advanced technical expertise across identity and access management, endpoint management, SaaS platforms, and cloud-integrated systems.Â
The IT Engineer II is expected to influence standards, mentor junior engineers, and proactively identify opportunities for automation, access governance, and process improvement. This role serves as a subject matter expert for identity lifecycle management, role-based access controls, and Okta platform administration.Â
Â
Position Responsibilities:Â
- Serve as a senior escalation point for complex or high-impact end-user and systems issues beyond Helpdesk and IT Engineer I scopeÂ
- Lead and deliver medium-to-large IT projects involving identity management, endpoint management, security controls, and SaaS platformsÂ
- Design, implement, and maintain scalable onboarding, offboarding, and identity lifecycle management processesÂ
- Administer and enhance Okta Identity Cloud, including authentication, authorization, application integrations, and access policiesÂ
- Design and maintain role-based access control (RBAC) frameworks to ensure appropriate access governance and least-privilege security modelsÂ
- Develop and maintain Okta Workflows to automate provisioning, deprovisioning, approval processes, and operational tasksÂ
- Configure and support Okta Identity Governance processes, including access requests, certifications, entitlement reviews, and lifecycle governance controlsÂ
- Partner with Security, Compliance, Engineering, and Business stakeholders to implement access governance and security best practicesÂ
- Evaluate, test, and deploy new software solutions, acting as the technical owner throughout rollout and adoptionÂ
- Develop and maintain technical documentation, runbooks, knowledge articles, and access governance proceduresÂ
- Identify recurring operational issues and implement systemic and automated solutions to improve efficiency and reduce riskÂ
- Mentor IT Engineer I team members and provide technical guidance across identity and access management disciplinesÂ
- Contribute scripts and automation using Bash, PowerShell, Python, or similar languagesÂ
- Participate in on-call or off-hours support rotations as requiredÂ
Â
Required Qualifications:Â
- 4–6+ years of experience in IT engineering, systems administration, identity and access management, or equivalent rolesÂ
- Proven ability to independently resolve complex technical issues and deliver end-to-end solutionsÂ
- Advanced experience administering and supporting Okta Identity CloudÂ
- Hands-on experience designing and implementing role-based access control (RBAC) models and access governance processesÂ
- Experience developing and maintaining Okta Workflows for identity automation and lifecycle managementÂ
- Experience implementing and administering Okta Identity Governance, including access requests, certifications, entitlement management, and lifecycle governanceÂ
- Strong experience managing:Â Â
- Identity and access management platformsÂ
- User provisioning and deprovisioning processesÂ
- Endpoint management and device lifecycle operationsÂ
- SaaS application deployment and governanceÂ
- Demonstrated experience leading medium-scale IT projects involving multiple systems or business stakeholdersÂ
- Ability to partner effectively with Security, Engineering, Compliance, and Business teamsÂ
- Proficiency administering Office 365 and supporting macOS in a remote-first environmentÂ
- Experience deploying, evaluating, and operationalizing new software solutionsÂ
- Working knowledge of at least one major cloud platform (AWS, Azure, or Google Cloud preferred)Â
- Strong scripting and automation skills using Bash, PowerShell, Python, or similar languagesÂ
- Experience mentoring junior engineers or providing technical guidance to peersÂ
- Comfortable participating in on-call or off-hours support rotationsÂ
Preferred Qualifications:Â
- Okta Certified Professional, Administrator, or Identity Governance certificationsÂ
- Experience with SCIM provisioning, SAML, OIDC, OAuth, and modern identity standardsÂ
- Experience performing access reviews, audit support, and compliance-focused identity governance activitiesÂ
- Experience integrating identity platforms with HRIS, MDM, ticketing, and security systemsÂ
- Experience supporting healthcare, financial services, or other regulated environments
All employees are responsible for adherence to the Judi Health Code of Conduct including the reporting of non-compliance. This position description is designed to be flexible, allowing management the opportunity to assign or reassign duties and responsibilities as needed to best meet organizational goals.
We provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, medical condition, genetic information, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.Â
By submitting an application, you agree to the retention of your personal data for consideration for a future position at Judi Health. More details about Judi Health's privacy practices can be found at https://www.judi.health/legal/privacy-policy.
IT Engineer II - IAM · Judi Health